Lucene search

K

F5 Networks, Inc. Security Vulnerabilities

osv
osv

CVE-2023-23900

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in YIKES, Inc. Easy Forms for Mailchimp plugin <= 6.8.8...

6.1CVSS

6.1AI Score

0.0005EPSS

2023-08-10 12:15 PM
11
osv
osv

CVE-2023-4925

The Easy Forms for Mailchimp WordPress plugin through 6.8.10 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is...

4.8CVSS

6AI Score

0.0004EPSS

2024-01-15 04:15 PM
11
osv
osv

CVE-2021-4244

A vulnerability classified as problematic has been found in yikes-inc-easy-mailchimp-extender Plugin up to 6.8.5. This affects an unknown part of the file admin/partials/ajax/add_field_to_form.php. The manipulation of the argument field_name/merge_tag/field_type/list_id leads to cross site...

6.1CVSS

6AI Score

0.001EPSS

2022-12-12 02:15 PM
7
osv
osv

CVE-2023-1323

The Easy Forms for Mailchimp WordPress plugin before 6.8.9 does not sanitise and escape some of its from parameters, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite.....

4.8CVSS

5.8AI Score

0.0005EPSS

2023-06-12 06:15 PM
10
osv
osv

CVE-2023-1324

The Easy Forms for Mailchimp WordPress plugin before 6.8.8 does not sanitise and escape some parameters before outputting them back in the response, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as...

6.1CVSS

6.2AI Score

0.001EPSS

2023-04-24 07:15 PM
10
osv
osv

CVE-2023-1325

The Easy Forms for Mailchimp WordPress plugin before 6.8.7 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting...

5.4CVSS

6AI Score

0.001EPSS

2023-04-17 01:15 PM
8
osv
osv

CVE-2023-2518

The Easy Forms for Mailchimp WordPress plugin before 6.8.9 does not sanitise and escape a parameter before outputting it back in the page when the debug option is enabled, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as...

6.1CVSS

6.2AI Score

0.001EPSS

2023-05-30 08:15 AM
9
githubexploit
githubexploit

Exploit for Command Injection in Vmware Aria Operations For Networks

CVE-2023-20887 POC for CVE-2023-20887 VMWare Aria Operations...

9.8CVSS

10AI Score

0.971EPSS

2023-06-13 01:17 PM
420
cve
cve

CVE-2023-20887

Aria Operations for Networks contains a command injection vulnerability. A malicious actor with network access to VMware Aria Operations for Networks may be able to perform a command injection attack resulting in remote code...

9.8CVSS

9.8AI Score

0.971EPSS

2023-06-07 03:15 PM
419
In Wild
nuclei
nuclei

VMware Aria Operations for Networks - Remote Code Execution

Aria Operations for Networks contains an authenticated deserialization vulnerability. A malicious actor with network access to VMware Aria Operations for Networks and valid 'member' role credentials may be able to perform a deserialization attack resulting in remote code...

8.8CVSS

8.9AI Score

0.248EPSS

2023-06-27 08:37 AM
7
githubexploit
githubexploit

Exploit for Use of a Broken or Risky Cryptographic Algorithm in Vmware Aria Operations For Networks

CVE-2023-34039 POC for CVE-2023-34039 VMWare Aria Operations...

9.8CVSS

7.3AI Score

0.945EPSS

2023-09-01 04:17 PM
210
cve
cve

CVE-2024-22238

Aria Operations for Networks contains a cross site scripting vulnerability. A malicious actor with admin privileges may be able to inject malicious code into user profile configurations due to improper input...

6.4CVSS

6.1AI Score

0.0004EPSS

2024-02-06 08:16 PM
22
nuclei
nuclei

VMware Aria Operations for Networks - Code Injection Information Disclosure Vulnerability

Aria Operations for Networks contains an information disclosure vulnerability. A malicious actor with network access to VMware Aria Operations for Networks may be able to perform a command injection attack resulting in information...

7.5CVSS

7.5AI Score

0.488EPSS

2023-06-27 08:41 AM
7
nuclei
nuclei

Palo Alto Networks PAN-OS Web Interface - Cross Site-Scripting

PAN-OS management web interface is vulnerable to reflected cross-site scripting. A remote attacker able to convince an administrator with an active authenticated session on the firewall management interface to click on a crafted link to that management web interface could potentially execute...

8.8CVSS

8.1AI Score

0.031EPSS

2021-02-14 08:00 PM
8
nuclei
nuclei

Palo Alto Networks PAN-OS GlobalProtect <8.1.4 - Cross-Site Scripting

Palo Alto Networks PAN-OS before 8.1.4 GlobalProtect Portal Login page allows an unauthenticated attacker to inject arbitrary JavaScript or HTML, making it vulnerable to cross-site...

6.1CVSS

6AI Score

0.001EPSS

2021-05-02 07:26 PM
5
nessus
nessus

Extreme Networks ExtremeXOS Detection

Extreme Networks ExtremeXOS was detected on the remote...

7.4AI Score

2023-12-07 12:00 AM
2
nessus
nessus

Arista Networks Device Detection

Nessus was able to obtain version information for an Arista Networks device via an SSH login or by examining SNMP services running on the...

4.1AI Score

2018-02-28 12:00 AM
12
openvas
openvas

Aerohive Networks HiveOS RCE Vulnerability

Aerohive HiveOS is prone to a remote command execution (RCE) ...

7.6AI Score

2017-06-16 12:00 AM
87
osv
osv

Data exfiltration from internal networks in github.com/docker/docker

dockerd forwards DNS requests to the host loopback device, bypassing the container network namespace's normal routing semantics, networks marked as 'internal' can unexpectedly forward DNS requests to an external nameserver. By registering a domain for which they control the authoritative...

5.9CVSS

6.6AI Score

0.0004EPSS

2024-03-22 06:49 PM
7
nessus
nessus

Extreme Networks ExtremeXOS Web Detection

The web interface for Extreme Networks ExtremeXOS was detected on the remote. Note that HTTP form credentials are required to retrieve version...

7.3AI Score

2023-11-13 12:00 AM
5
osv
osv

CVE-2023-38698

Ethereum Name Service (ENS) is a distributed, open, and extensible naming system based on the Ethereum blockchain. According to the documentation, controllers are allowed to register new domains and extend the expiry of existing domains, but they cannot change the ownership or reduce the...

6.5CVSS

7.2AI Score

0.001EPSS

2023-08-04 06:15 PM
8
wpvulndb
wpvulndb

NextScripts: Social Networks Auto-Poster < 4.4.4 - Subscriber+ Sensitive Information Exposure

Description The plugin is vulnerable to Sensitive Information Exposure via the 'nxs_getExpSettings' function. This makes it possible for authenticated attackers, with subscriber access and above, to extract sensitive data including social network API keys and...

8.5CVSS

6.5AI Score

0.001EPSS

2024-05-22 12:00 AM
1
nessus
nessus

Arista Networks EOS DoS (SA0087)

On affected platforms running Arista EOS, a malformed DHCP packet might cause the DHCP relay agent to restart. Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version...

7.5CVSS

7.6AI Score

0.001EPSS

2024-02-01 12:00 AM
3
githubexploit
githubexploit

Exploit for CVE-2023-38831

CVE-2023-38831 PoC (Proof Of Concept) This is an easy to use...

7.8CVSS

8.3AI Score

0.192EPSS

2023-08-28 04:56 AM
248
openbugbounty
openbugbounty

inc-conso.fr Cross Site Scripting vulnerability OBB-3872425

Following the coordinated and responsible vulnerability disclosure guidelines of the ISO 29147 standard, Open Bug Bounty has: a. verified the vulnerability and confirmed its existence; b. notified the website operator about its existence. Technical details of the vulnerability are currently...

6.2AI Score

2024-03-14 02:53 PM
8
nessus
nessus

Arista Networks EOS Memory Exhaustion (SA0084)

On affected platforms running Arista EOS with SNMP configured and the snmpd process is running, a specially crafted SNMP packet can cause a memory leak in the snmpd process. This may result in the snmpd processing being terminated (causing SNMP requests to time out until snmpd is automatically...

7.5CVSS

6.3AI Score

0.001EPSS

2023-07-31 12:00 AM
3
nessus
nessus

Palo Alto Networks PAN-OS Version Detection

The remote host is running Palo Alto Networks PAN-OS, an operating system for Palo Alto firewall devices. It was possible to read the PAN-OS version number by logging into the device via SSH or...

2.1AI Score

2014-03-05 12:00 AM
21
nessus
nessus

Palo Alto Networks PAN-OS Compliance Checks

Using the supplied credentials, this script performs a compliance check against the given...

1.2AI Score

2013-02-19 12:00 AM
18
githubexploit
githubexploit

Exploit for Use After Free in Linux Linux Kernel

CVE-2022-2586-LPE LPE N-day Exploit for...

7.8CVSS

7.2AI Score

0.01EPSS

2022-09-03 07:04 PM
1104
nessus
nessus

F5 Networks BIG-IP : glibc vulnerability (K47098834)

Multiple stack-based buffer overflows in the (1) send_dg and (2) send_vc functions in the libresolv library in the GNU C Library (aka glibc or libc6) before 2.23 allow remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted DNS response that triggers.....

8.1CVSS

8.6AI Score

0.974EPSS

2016-02-17 12:00 AM
31
nessus
nessus

F5 Networks BIG-IP : Kernel vulnerability (K62442245)

The tcp_check_send_head function in include/net/tcp.h in the Linux kernel before 4.7.5 does not properly maintain certain SACK state after a failed data copy, which allows local users to cause a denial of service (tcp_xmit_retransmit_queue use-after-free and system crash) via a crafted SACK...

5.5CVSS

6.3AI Score

0.0004EPSS

2019-03-06 12:00 AM
131
cve
cve

CVE-2017-17688

The OpenPGP specification allows a Cipher Feedback Mode (CFB) malleability-gadget attack that can indirectly lead to plaintext exfiltration, aka EFAIL. NOTE: third parties report that this is a problem in applications that mishandle the Modification Detection Code (MDC) feature or accept an...

5.9CVSS

5.7AI Score

0.008EPSS

2018-05-16 07:29 PM
46
nessus
nessus

Palo Alto Networks PAN-OS VPN Enabled Detection

VPN is enabled on the remote Palo Alto...

2.2AI Score

2020-11-06 12:00 AM
7
nessus
nessus

Palo Alto Networks User-ID Agent Version Detection

Palo Alto Networks User-ID agent, a monitoring and reporting service that supports user and group mapping for firewall configurations, is installed on the remote...

1.6AI Score

2016-06-17 12:00 AM
16
osv
osv

CVE-2023-28842

Moby) is an open source container framework developed by Docker Inc. that is distributed as Docker, Mirantis Container Runtime, and various other downstream projects/products. The Moby daemon component (dockerd), which is developed as moby/moby is commonly referred to as Docker. Swarm Mode, which.....

8.7CVSS

7.2AI Score

0.003EPSS

2023-04-04 10:15 PM
13
osv
osv

CVE-2023-28841

Moby is an open source container framework developed by Docker Inc. that is distributed as Docker, Mirantis Container Runtime, and various other downstream projects/products. The Moby daemon component (dockerd), which is developed as moby/moby is commonly referred to as Docker. Swarm Mode, which...

8.7CVSS

7AI Score

0.003EPSS

2023-04-04 10:15 PM
7
nessus
nessus

F5 Networks ARX Data Manager Web Interface Detection

The web interface login page for F5 Networks ARX Data Manager was detected on the remote host. ARX Data Manager is a product for file storage management and...

1.8AI Score

2014-07-01 12:00 AM
15
nessus
nessus

Palo Alto Networks PAN-OS CVE-2024-3400

The version of Palo Alto Networks PAN-OS running on the remote host is affected by a command injection vulnerability as a result of arbitrary file creation vulnerability in the GlobalProtect feature of Palo Alto Networks PAN-OS software for specific PAN-OS versions and distinct feature...

10CVSS

10AI Score

0.957EPSS

2024-04-12 12:00 AM
77
nessus
nessus

F5 Networks BIG-IP : libxml2 vulnerability (K000139592)

The version of F5 Networks BIG-IP installed on the remote host is prior to tested version. It is, therefore, affected by a vulnerability as referenced in the K000139592 advisory. An issue was discovered in libxml2 before 2.10.4. When hashing empty dict strings in a crafted XML document,...

6.5CVSS

7AI Score

0.001EPSS

2024-05-14 12:00 AM
5
wpvulndb
wpvulndb

NextScripts: Social Networks Auto-Poster < 4.4.4 - Unauthenticated Stored Cross-Site Scripting via User Agent

Description The NextScripts: Social Networks Auto-Poster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the HTTP_USER_AGENT header in all versions up to, and including, 4.4.3 due to insufficient input sanitization and output escaping. This makes it possible for...

6.1CVSS

6.2AI Score

0.0004EPSS

2024-05-21 12:00 AM
1
wpvulndb
wpvulndb

NextScripts: Social Networks Auto-Poster < 4.4.4 - Cross-Site Request Forgery to Arbitrary Post Deletion

Description The NextScripts: Social Networks Auto-Poster plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.4.3. This is due to missing or incorrect nonce validation on the nxssnap-reposter page. This makes it possible for unauthenticated...

5.4CVSS

6.5AI Score

0.0005EPSS

2024-05-21 12:00 AM
2
cvelist
cvelist

CVE-2024-0552 Intumit inc. SmartRobot - Remote Code Execution

Intumit inc. SmartRobot's web framwork has a remote code execution vulnerability. An unauthorized remote attacker can exploit this vulnerability to execute arbitrary commands on the remote...

9.8CVSS

10AI Score

0.002EPSS

2024-01-15 04:03 AM
3
nessus
nessus

F5 Networks BIG-IP : GSON vulnerability (K00994461)

The version of F5 Networks BIG-IP installed on the remote host is prior to tested version. It is, therefore, affected by a vulnerability as referenced in the K00994461 advisory. The package com.google.code.gson:gson before 2.8.9 are vulnerable to Deserialization of Untrusted Data via the...

7.7CVSS

7.8AI Score

0.002EPSS

2022-08-29 12:00 AM
92
nessus
nessus

F5 Networks BIG-IP : VPN TunnelVision vulnerability (K000139553)

The version of F5 Networks BIG-IP installed on the remote host is prior to tested version. It is, therefore, affected by a vulnerability as referenced in the K000139553 advisory. By design, the DHCP protocol does not authenticate messages, including for example the classless static route...

7.6CVSS

7.7AI Score

0.0005EPSS

2024-05-21 12:00 AM
4
nessus
nessus

F5 Networks BIG-IQ Configuration Utility Login Page Detection

The configuration utility login page for F5 Networks BIG-IQ was detected on the remote host. BIG-IQ is a product for managing BIG-IP...

1.6AI Score

2014-05-09 12:00 AM
10
openvas
openvas

Dasan Networks GPON ONT Devices Multiple Vulnerabilities - Active Check

Dasan Networks GPON ONT devices are prone to multiple ...

7.4AI Score

2017-07-14 12:00 AM
14
githubexploit
githubexploit

Exploit for CVE-2024-5522

CVE-2024-5522-Poc CVE-2024-5522 HTML5 Video Player &lt;=...

8.2AI Score

0.0004EPSS

2024-05-31 04:41 AM
248
nessus
nessus

F5 Networks BIG-IP : Oracle Java SE vulnerability (K73112451)

Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to JMX....

9.8CVSS

7.3AI Score

0.49EPSS

2016-12-21 12:00 AM
140
nessus
nessus

F5 Networks BIG-IP : libxml2 vulnerability (K000139594)

The version of F5 Networks BIG-IP installed on the remote host is prior to tested version. It is, therefore, affected by a vulnerability as referenced in the K000139594 advisory. An issue was discovered in libxml2 before 2.10.3. Certain invalid XML entity definitions can corrupt a hash table...

7.8CVSS

7.3AI Score

0.001EPSS

2024-05-14 12:00 AM
4
nessus
nessus

F5 Networks BIG-IP : PyYAML vulnerability (K000139901)

The version of F5 Networks BIG-IP installed on the remote host is prior to tested version. It is, therefore, affected by a vulnerability as referenced in the K000139901 advisory. In PyYAML before 5.1, the yaml.load() API could execute arbitrary code if used with untrusted data. The load()...

9.8CVSS

8.1AI Score

0.014EPSS

2024-06-05 12:00 AM
1
Total number of security vulnerabilities315010